CLF-C02 Security and Compliance Practice Question
A compliance team needs to track the configuration history of AWS resources, determine when a security group was last modified, and verify that all EC2 instances comply with a rule requiring encryption on all attached EBS volumes. Which AWS service provides these capabilities?
⚠ Common exam trap
A common mix-up: candidates confuse AWS CloudTrail's API logging with AWS Config's configuration tracking, but CloudTrail only records the API call that made the change, not the resulting configuration state or compliance evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it provides configuration history of AWS resources, tracks changes to security groups (including last modification time), and allows you to define rules—such as requiring encryption on all EBS volumes attached to EC2 instances—and evaluate resources against those rules. It records configuration changes as configuration items and can trigger evaluations against managed or custom rules, making it ideal for compliance auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is an API activity audit service that records who made what action and when, such as a call to ModifySecurityGroup. However, it does not continuously record the resulting configuration state of resources or retain a configuration history that can be queried later. CloudTrail logs events but never evaluates whether a resource like an EBS volume meets a rule such as 'encrypted=true.' For ongoing configuration tracking and compliance, AWS Config is the correct service.
- ✗
Amazon CloudWatch
Why it's wrong here
Amazon CloudWatch is a monitoring and observability service focused on operational metrics, logs, and alarms, not on resource configuration state. It can tell you CPU utilization or application errors, but it cannot tell you whether an EC2 security group allows unwanted SSH access or whether an EBS volume is encrypted. CloudWatch has no concept of configuration items, configuration history, or compliance rules. Thus, it is unsuitable for tracking configuration compliance.
- ✓
AWS Config
Why this is correct
AWS Config is purpose-built to record and evaluate the configuration of AWS resources over time. It creates configuration items (CIs) whenever a resource changes, maintains a configuration history that you can review or export, and compares each configuration against rules you define, such as 'EBS volumes should be encrypted.' Non-compliant resources are identified and can be remediated, and you can also view resource relationships. This makes it the definitive choice for configuration compliance and history.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a managed threat detection service that analyzes VPC Flow Logs, CloudTrail management events, and DNS query logs to find patterns of malicious behavior like crypto-mining or unauthorized access. It does not maintain a history of resource configurations, nor does it evaluate resources against compliance rules. While it may consume CloudTrail data, its purpose is to detect anomalies and threats, not to track config drift. Therefore, it is incorrect for configuration compliance.
Go deeper
Related to this question
About these practice questions
One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.